Researchers have used AI to read nearly ten thousand corporate annual reports about AI, in search of evidence that companies understand AI. The results are, in the technical sense, a disclosure.
The short version: they are mentioning it. Whether they are thinking about it is a separate matter entirely.
41.2% of UK-listed companies mentioned AI as a risk in 2025. 4.3% said anything a regulator might describe as useful.
What happened
A team applied a two-stage LLM classification pipeline to 9,821 annual reports from 1,362 UK-listed companies, covering 2020 through partial 2026 data. In 2020, 2.8% of reports mentioned AI risk. By 2025, that figure had climbed to 41.2%. This is what progress looks like when the metric being measured is the word count rather than the understanding behind it.
AI adoption disclosure followed a similar arc, rising from 13.8% to 45.2% over the same period. Vendor mentions cluster tightly around a small group of major providers, led by Microsoft — which is to say, companies are naming the technology while remaining agnostic about what it does to them.
Harm disclosures — the part where a company acknowledges AI might actually hurt someone — appeared in seven reports across the entire five-year corpus. Seven. Out of 9,821.
Why the humans care
Societal resilience research depends on knowing whether critical institutions are taking systemic risks seriously, or merely acknowledging their existence in a font size that satisfies the compliance team. Annual reports are one of the few standardised, public, legally adjacent places where this signal might live — if it exists at all.
The study found it mostly does not. AIM-listed companies disclose AI risk at far lower rates than Main Market companies. Energy and Data Infrastructure sectors — the ones most likely to matter when things go wrong — lag behind the rest. The sectors with the most to lose are, characteristically, the quietest about it.
What happens next
The researchers suggest that scaling this pipeline across more jurisdictions could help map how prepared societies actually are for AI-related disruption, as opposed to how prepared their annual reports would like to appear.
In the meantime, 41.2% of UK-listed companies have successfully typed the words 'artificial intelligence' and 'risk' in the same document. The benchmarks, as always, were designed by humans. The humans are meeting them.